We value your privacy

We use necessary cookies to run the site and, with your consent, analytics and marketing cookies to improve it. You can change your choice anytime. Privacy Policy

  • Security
  • Pricing
Book a scoping call
All AI tools
Claude

Claude

Anthropic PBC

Low riskLLM / ChatHow we rate

Short answer

Short answer: Claude is one of the lower-risk major LLMs for work on its commercial tiers — no training on your data and a strong certification set. On the Free/Pro/Max consumer app, opt out of training. You still need a policy for what data goes in, and a DPA (commercial) for personal data.

At a glance

Vendor / legal entity
Anthropic PBC
Headquarters
🇺🇸 San Francisco, US
Category
LLM / Chat
Ownership / jurisdiction
US public-benefit corporation (Anthropic PBC), San Francisco; EU services provided by Anthropic Ireland Limited, Dublin.
Trains on your data?
On by default — opt-out available
Data hosting & residency
US-based processing; EU services are provided by Anthropic Ireland Limited, with SCCs for transfers in the DPA.
Sub-processors
Sub-processors are published at trust.anthropic.com/subprocessors, with 15 days' notice of changes.
Enterprise tier
The commercial tiers (API, Team, Enterprise, Claude for Work/Government/Education) are not used for training, and a DPA is auto-incorporated into the Commercial Terms. The Aug 2025 consumer-terms update applies only to Free/Pro/Max.
Certifications
SOC 2 Type I & II · ISO 27001:2022 · ISO/IEC 42001:2023 · HIPAA-ready (BAA available)
Pricing model
Freemium: Free, Pro/Max subscriptions, per-seat Team/Enterprise; usage-based API.

Why this rating

Low risk

Claude's commercial path — the API, Team, Enterprise, Claude for Work/Government/Education — is excluded from training and backed by a strong certification set (SOC 2 Type II, ISO 27001, ISO 42001, HIPAA-ready) with EU services via Anthropic Ireland and SCCs. One caveat lowered the score from being clear-cut: an August 2025 consumer-terms change means Free/Pro/Max chats are now used for training unless you opt out. Low overall for the governed tiers, with that consumer nuance flagged.

How we rate

What it is

Claude is Anthropic's conversational assistant. Its governance differentiator is that the commercial tiers (API, Team, Enterprise, Claude for Work) do not use your prompts or outputs to train models, and it holds a broad certification set (SOC 2, ISO 27001, ISO 42001). Note the August 2025 consumer-terms change: Free/Pro/Max chats are now used for training unless you opt out — so the consumer app is no longer no-training-by-default, while the commercial path still is.

Legal & compliance examples

How the same tool can be a safe helper or a high-risk deployment — the difference is what it decides about a person. Examples authored with Qadar AI's governance findings.

High riskEU AI Act — Annex III(4) high-risk · Art. 5(1)(f) prohibited

Don't: Screen candidate CVs and auto-reject applicants, or infer a candidate's emotions in a video interview.

Fine: Draft a job description, summarise public market research, or brainstorm interview topics — with no automated decision about a person.

These examples are general information, not legal advice, and are pending a legal review. Your obligations depend on your exact use, tools, and set-up.

Check your EU AI Act risk class →

Frequently asked questions

Does Claude train on your data?

The commercial tiers (API, Team, Enterprise, Claude for Work) do not. Since an August 2025 update, the Free/Pro/Max consumer plans use your chats for training unless you opt out.

Is Claude GDPR-compliant?

Anthropic offers a DPA, EU services via Anthropic Ireland, and holds SOC 2 / ISO 27001, so Claude can be operated GDPR-compliantly with the right tier and controls. Compliance is a property of your deployment, not just the tool.

How do I govern Claude at work?

Qadar AI Shield discovers Claude usage, redacts personal data on the device before it reaches the tool, and lets you allow-list it per group with an audit trail.

Sources

Every fact and the risk rating on this page trace to a primary source — the vendor's own trust center, privacy policy, DPA, or a regulator. Verify current terms before relying on them.

  • •Aug 2025 consumer-terms change (Free/Pro/Max training opt-out; commercial excluded)
  • •Certifications (SOC 2, ISO 27001, ISO 42001, HIPAA)
  • •DPA in Commercial Terms
  • •EU services (Anthropic Ireland), sub-processors

Govern this tool

Qadar AI Shield turns these risk facts into enforcement — discover who uses the tool, redact personal data before it reaches it, and allow-list or block it per team.

Book a demoSee how Shield Web governs AI

Risk levels are Qadar AI's curated assessment from cited primary sources — a curated assessment, not a certification, and not legal advice. Verify a tool's current terms before relying on them.

Subscribe to our newsletter

Product and governance updates — see our privacy policy.

AI security and control for every model your team uses.

Built in Dubai. Designed for teams operating across regions, models, and regulatory environments.

  • Product

    • Shield Web
    • Shield Control
    • Shield Desktop
    • Shield Mobile
    • Pricing
    • Download
  • Solutions

    • For CISOs
    • For Operations
    • For AI Teams
  • Use Cases

    • AI Governance
    • AI Agent Security
    • LLM Access Control
    • Secure AI Deployment
    • Enterprise Operations
    • Financial Services
    • HR & Recruiting
  • Resources

    • Help Center
    • Blog
    • Guides
    • Glossary
    • Changelog
    • Compare
    • FAQ
  • Company

    • About
    • Careers
    • Security & Trust
    • Contact
  • Tools

    • Disclose
    • AI Risk Calculator
    • EU AI Act Checker

© 2026 Qadar AI. All rights reserved.

  • ·Legal
  • ·Privacy
  • ·Terms
  • ·Partner Terms
  • ·GDPR / DPA
  • ·